iblai-api-agent-eval
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill acts as an API wrapper for the author's platform.
- [DATA_EXFILTRATION]: The skill communicates with api.iblai.app to manage evaluation data and experiments. This domain is verified as a resource belonging to the skill author (iblai) and its use is consistent with the primary purpose of the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of external datasets and chat traces for evaluation purposes, representing a vulnerability surface.
- Ingestion points: Evaluation items can be created via JSON, CSV upload, or linked from existing chat traces as defined in SKILL.md.
- Boundary markers: The instructions do not define specific prompt delimiters or instructions to ignore embedded content within the datasets.
- Capability inventory: The agent has the capability to trigger background experiment runs and automated LLM-as-Judge scoring.
- Sanitization: There is no explicit requirement or logic for sanitizing or filtering external content before it is processed by the evaluation engine.
Audit Metadata